
Ammar Askar
93 posts




Mythos broke into almost all of the NSA’s classified systems in hours, per its director. It would have been irresponsible to not impose export controls on it. (And on Fable, with its pathetically inadequate guardrails.)


“so you found a critical vulnerability and just publicly disclosed it?” “Yes, Dave” “And the vulnerability was fixed in record time?” “That’s correct Dave” “Sounds like responsible disclosure to me” “Precisely”





Yeah, so pretty much this guy is releasing an exploit in solidarity with Nightmare Eclipse guy. He said he notified GitHub about the exploit 60 minutes before releasing this paper. I don't do web stuff, and I'm not a VSCode nerd, so I'm confused by the underlying technologies. If you're a stinky GitHub and VSCode nerd maybe you'll understand. tl;dr click github dev, github dev opens editor, in github dev editor have javascript, javascript does shortcuts automatically. github treats javascript shortcuts as real human input, or something. use javascript shortcut stuff to automatically install vscode extension. the vscode extension steals your data tl;dr tl;dr user clicks 1 link, 1 click steals all data from your github blog.ammaraskar.com/github-token-s…









Sending unwavering support to @__phantomderp in the face of only wanting to continue to provide their expertise to their programming community. I condemn the RANCID remarks made publicly about them by a PSF Fellow.

Techbros stop figuring new ways to showcase their racism: still impossible






